Changelog
What is new in Inventoros
Every release, straight from GitHub. Follow along as Inventoros grows.
Release v2.0.0
October 6, 2026
View on GitHubInventoros 2.0.0
Inventoros 2.0.0 expands the inventory core with shipping, payments, customer portals, approvals, scheduled reports, multi-organization memberships and a runtime plugin platform. This is the first release after 1.0.8.
Upgrading from 1.0.x
Upgrade manually once. The updater shipped in 1.0.8 and earlier cannot follow GitHub's release-download redirects. Back up your database and files, drain active work, and follow the upgrade guide. Clear old caches before migrating. PHP 8.4.1 or newer is required; PHP 8.4 and 8.5 are supported. The scheduler must run every minute.
Other compatibility changes include snake_case MCP tool names, plugin assets moving to
public/plugin-assets, bearer-token-only REST authentication and AGPL-3.0-only licensing. Releases through 1.0.8 remain MIT licensed.Highlights
- Shipping and fulfilment with EasyPost or manual shipments, partial shipment support, tracking and shipment emails.
- Customer portal, line/order discounts, payments, refunds, invoices and currency-aware receivables and analytics.
- Optional approval workflows, scheduled cycle counts and report emails, expanded barcode scanning and warehouse access controls.
- Organization memberships and switching, organization-bound API tokens and atomic inter-company stock transfers.
- Signed plugin marketplace, runtime plugin pages/widgets/tabs, additional lifecycle hooks, plugin MCP tools and webhook events, and a documented core PHP extension API.
- Production Docker image and a signed cPanel package with compiled assets, production Composer dependencies and a verified release manifest.
Release audit fixes
The release audit tightened tenant access to installation updates/backups, serialized stock-operation transitions, rechecked scheduled-report recipients at delivery, fixed queue reservation lifetimes, capped low-stock reports, improved update rollback behavior and persisted Docker plugins across services. It also fixed guest-member cycle counts, plugin query isolation and variant transfer webhook payloads. Vue, source-map-js and shell-quote security fixes are included.
Downloads
- cPanel/shared hosting:
inventoros-cpanel-2.0.0.zipand its detached Ed25519 signature,inventoros-cpanel-2.0.0.zip.sig. FollowINSTALL.mdinside the archive. No Node.js build is needed on the server. - Docker:
ghcr.io/inventoros/inventoros:2.0.0, with Docker deployment instructions. - Example plugin:
hello-world-plugin.zip. Prefer the signed marketplace copy when listed; manual ZIP uploads requireINVENTOROS_ALLOW_PLUGIN_UPLOADS=true.
Known limits and next work
Stock reservations/available-to-promise are planned and are not included. Work orders currently support untracked, non-variant products; tracked products and virtual kits are refused to preserve inventory integrity. Inter-company transfers do not move batch/serial-tracked stock or kits.
Organization membership administration screens and business-specific 3PL workflows remain plugin work. Some notification/assignee pickers still list home-organization users only. Large cycle-count performance, expired-export cleanup and the Tailwind 3 development dependency advisories remain follow-up work. Production npm and Composer dependency audits pass.
See the full changelog and release audit for details and the prioritized backlog.
Release v1.0.8
August 2, 2026
View on GitHubInventoros v1.0.8
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.8.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.7
August 2, 2026
View on GitHubInventoros v1.0.7
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.7.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.6
July 22, 2026
View on GitHubInventoros v1.0.6
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.6.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.5
July 22, 2026
View on GitHubInventoros v1.0.5
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.5.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.4
July 22, 2026
View on GitHubInventoros v1.0.4
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.4.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.3
June 5, 2026
View on GitHubInventoros v1.0.3 — Security & Reliability
Implements every actionable finding from the 2026-06-03 security + reliability audit, each with regression tests. Full test suite green (1255 tests); cPanel package is now signed.
Security
- Plugin slug path containment (reject traversal/separators + realpath-contained deletes)
- GraphQL category/location references scoped to the caller's organization (IDOR)
- Update-availability check requires admin; backup filenames validated against an allowlist + the known-backup set
- GraphQL free-text length caps to match REST
- SSRF guard fails closed on empty DNS in production
- Nonce-based Content-Security-Policy (Vite + Ziggy nonce, vue-i18n JIT); deprecated X-XSS-Protection removed
- Plugin manifest guard + a startup warning when uploads are enabled without signature verification
Reliability / data integrity
- Shared, locked cancel-restock across web/REST/GraphQL (GraphQL no longer leaks stock on cancel)
- Transactions + row locks + status re-checks on PO receiving, work-order complete/cancel, stock-audit complete, web order cancel, and return receive
- Org-scoped, fail-fast product lookup in web order updates
- Stock notifications deferred until after the locked transaction commits
- All advertised webhook events now actually dispatch (stock, order, and purchase-order lifecycle)
- In-app updater auto-restores from backup if file replacement fails
- Product imports retry transient failures and keep the upload until the final attempt
Signed updates
Release archives are now signed with a detached Ed25519 signature (
inventoros-cpanel-1.0.3.zip.sig). The in-app updater verifies the archive against the public key shipped in.env.examplebefore extracting. SetINVENTOROS_UPDATE_PUBLIC_KEY(already in.env.example); to install unsigned builds setINVENTOROS_UPDATE_SIGNATURE_REQUIRED=false.Known limitation
Stock transfers between locations remain a no-op audit record (global stock model); per-location stock tracking is a future change.
See
INSTALL.mdinside the zip for cPanel installation steps.Release v1.0.2
April 6, 2026
View on GitHubInventoros v1.0.2
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.2.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.1B-CPANEL
December 22, 2025
View on GitHubInventoros v1.0.1B-CPANEL
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.1B-CPANEL.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Release v1.0.0B-CPANEL-B
December 14, 2025
View on GitHubInventoros v1.0.0B-CPANEL-B
cPanel Installation Package
This release includes a pre-built package optimized for cPanel shared hosting.
Download:
inventoros-cpanel-1.0.0B-CPANEL-B.zipSee
INSTALL.mdinside the zip for installation instructions.What's Included
- Pre-compiled frontend assets (no npm required on server)
- Production-optimized Composer dependencies
- cPanel-compatible directory structure
- Modified index.php for split directory setup
Version 1.0BETA
October 14, 2025
View on GitHubWe’re officially launching Inventoros v1.0BETA — our first public milestone in reshaping the open-source inventory and warehouse management landscape.
⚠️ Active Development Disclaimer: Inventoros is still in early-stage development. Core features are functional, but APIs, UI flows, and plugin behavior remain fluid as we stabilize for production readiness. Early adopters and contributors are encouraged to jump in, test, and provide feedback as we harden the platform.
Vision: To democratize warehouse and inventory management by giving small and medium-sized businesses enterprise-grade power wrapped in a developer-friendly, extensible framework.
Highlights in 1.0BETA
✅ Full CRUD product & order management with auto-inventory sync
✅ Role-based access control and multi-user architecture
✅ Plugin-ready system with hooks and filters
✅ Installer wizard with environment validation
✅ Multi-currency and responsive dark-mode UI
🚧 CSV import/export and analytics dashboards in active development
Stack: Laravel 12 · Inertia.js · Vue 3 · Vite · MySQL
Run the latest Inventoros
Updating is straightforward. The docs walk you through upgrades and backups.